Cyber Incident Response Lead

Cyber Incident Response Lead

Nottingham Full-Time 43200 - 72000 £ / year (est.) No home office possible
B

At a Glance

  • Tasks: Lead incident response efforts to tackle complex cybersecurity threats and ensure business recovery.
  • Company: Join Experian, a global leader in data and technology, empowering businesses and individuals worldwide.
  • Benefits: Enjoy flexible working options, competitive pay, generous leave, and a supportive work culture.
  • Why this job: Be part of a dynamic team making a real impact in cybersecurity while developing your skills.
  • Qualifications: Knowledge of network protocols, security technologies, and experience with SIEM tools required.
  • Other info: This role offers opportunities for mentorship and professional growth in a diverse environment.

The predicted salary is between 43200 - 72000 £ per year.

Company Description

Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to realise their financial goals and help them save time and money. We invest in people and new advanced technologies to unlock the power of data. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), we have a team of 22,500 people across 32 countries. Our corporate headquarters are in Dublin, Ireland.

Job Description

As a member of Experian's Global Security Office (EGSO) / Cyber Fusion Center (CFC) you will respond, contain, escalate, investigate, and coordinate mitigation of security events relative to anomalies detected and escalated by the Cyber Fusion Centre (CFC) according to Experian's Incident Response Plan. This team member will join a new, growing team of specialized, advanced responders to support escalations of complex or prioritized matters from Experian's existing 24x7 security monitoring and response functions responsible for responding to and analysing security incidents involving threats targeting Experian information assets. These threats may include phishing, malware, network attacks, suspicious activity. Also, you will involve working with end-users, partners, technical support teams, and management to ensure remediation and recovery from these threats. Use analytics & data collected from endpoints, environmental logging, and a variety of other sources to maximise containment and eradication of threats, while expediting recovery of the business. Please note you will have a regular Monday to Friday schedule and expectation to participate in on-call schedule or work outside of normal work hours to manage cybersecurity incidents. You will report to the CFC Senior Director of Incident Management and Security Operations.

Main Responsibilities include:

  • Conduct advanced incident response activities to investigate and contain complex and larger-scale cybersecurity matters (such as potential major severity incidents).
  • In the event of investigative matters requiring additional analytical support from teams such as Forensics and Cyber Threat Hunt workstreams across the teams and hold responsibility for expressing the CFC's overall understanding of the timeline of attacker activity so that appropriate containment and remediation actions can be coordinated.
  • Respond to Security to cyber security events and alerts associated to threats, intrusions, and compromises per any applicable SLOs.
  • Manage multiple cases related to security incidents throughout the incident response lifecycle; including Analysis, Containment, Eradication, Recovery, and Lessons Learned.
  • Maintain case documentation, including notes, analysis findings, containment steps, and cause for each assigned security incident.
  • Maintain an understanding of common Operating Systems (Windows, Linux, Mac OS), Security Technologies (Anti-Virus, Intrusion Prevention), and Networking (Firewalls, Proxies).
  • Interpret device and application logs from a variety of sources (e.g. Firewalls, Proxies, Web Servers, System Logs, Splunk, Packet Captures) to identify cause and determine next steps for containment, eradication, and recovery.
  • Provide Advanced Support to analysts (Logs review, IP Block question).
  • Mentor other analysts (process question, tool usage).

Qualifications

  • Must have knowledge of network protocols (TCP/IP, UDP, ICMP), standard protocols (HTTP/S, DNS, SSH, SMTP, SMB), wireless networking, networking infrastructure, and network topologies (DMZ, VPN, WAN) and network technologies (WAF, IPS, Routers, Firewalls).
  • Experience with commercial & opensource SIEMs, full packet capture tools, and network analysis tools (Splunk, Wireshark, SOF-ELK).
  • Have a demonstrated knowledge of common intrusion methods and cyber-attack tactics, techniques, and procedures (TTPs).
  • Exhibit skills using common Incident Response and Security Monitoring applications such as SIEM (Splunk), EDR (FireEye HX, CrowdStrike Falcon, McAfee mVision EDR.), WAF, IPS.

Additional Information

Benefits Package Includes:

  • Flexible work environment, working hybrid or in the office if you prefer.
  • Great compensation package and discretionary bonus plan.
  • Core benefits include pension, bupa healthcare, sharesave scheme and more.
  • 25 days annual leave with 8 bank holidays and 3 volunteering days. You can purchase additional annual leave.

Experian is proud to be an Equal Opportunity and Affirmative Action employer. Innovation is an important part of Experian's DNA and practices, and our diverse workforce drives our success. Everyone can succeed at Experian and bring their whole self to work, irrespective of their gender, ethnicity, religion, colour, sexuality, physical ability or age. If you have a disability or special need that requires accommodation, please let us know at the earliest opportunity.

Cyber Incident Response Lead employer: Back on Track! Solutions

Experian is an exceptional employer, offering a dynamic work environment that fosters innovation and collaboration within the Cyber Incident Response team. With a strong commitment to employee growth, you will benefit from a flexible work culture, competitive compensation, and comprehensive benefits, including generous annual leave and healthcare options. Located in Dublin, Ireland, you will be part of a global team dedicated to redefining data security while enjoying the advantages of working for a FTSE 100 company that values diversity and inclusion.
B

Contact Detail:

Back on Track! Solutions Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Incident Response Lead

✨Tip Number 1

Familiarise yourself with the specific tools and technologies mentioned in the job description, such as Splunk, FireEye, and CrowdStrike. Having hands-on experience or certifications in these areas can significantly boost your credibility during interviews.

✨Tip Number 2

Network with professionals in the cybersecurity field, especially those who work at Experian or similar companies. Attend industry events, webinars, or local meetups to make connections that could lead to referrals or insider information about the role.

✨Tip Number 3

Prepare for potential technical interviews by brushing up on your knowledge of network protocols and common intrusion methods. Be ready to discuss real-world scenarios where you successfully managed security incidents.

✨Tip Number 4

Showcase your problem-solving skills and ability to work under pressure. During interviews, share examples of how you've effectively responded to security incidents in the past, highlighting your analytical approach and teamwork.

We think you need these skills to ace Cyber Incident Response Lead

Advanced Incident Response
Cybersecurity Analysis
Threat Detection and Mitigation
Network Protocols (TCP/IP, UDP, ICMP)
Security Technologies (Anti-Virus, Intrusion Prevention)
Operating Systems Knowledge (Windows, Linux, Mac OS)
Log Interpretation (Firewalls, Proxies, Web Servers)
SIEM Tools (Splunk, SOF-ELK)
Packet Capture Tools (Wireshark)
Incident Response Lifecycle Management
Mentoring and Training Skills
Analytical Thinking
Communication Skills
Attention to Detail

Some tips for your application 🫡

Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity, particularly in incident response. Use keywords from the job description to demonstrate that you meet the qualifications and have the necessary skills.

Craft a Compelling Cover Letter: In your cover letter, explain why you're passionate about cybersecurity and how your background aligns with the role of Cyber Incident Response Lead. Mention specific experiences where you've successfully managed security incidents.

Showcase Technical Skills: Clearly outline your technical skills related to network protocols, SIEM tools, and incident response applications. Provide examples of how you've used these skills in previous roles to resolve security issues.

Highlight Team Collaboration: Since the role involves working with various teams, emphasise your ability to collaborate effectively. Share examples of past experiences where you worked with cross-functional teams to address cybersecurity challenges.

How to prepare for a job interview at Back on Track! Solutions

✨Understand the Role

Make sure you thoroughly understand the responsibilities of a Cyber Incident Response Lead. Familiarise yourself with incident response processes, security technologies, and the specific threats mentioned in the job description, such as phishing and malware.

✨Showcase Your Technical Skills

Be prepared to discuss your experience with network protocols, SIEM tools, and incident response applications. Highlight any relevant projects or situations where you've successfully managed security incidents, demonstrating your technical expertise.

✨Prepare for Scenario-Based Questions

Expect scenario-based questions that assess your problem-solving skills in real-time incidents. Practice articulating your thought process on how you would respond to various cyber threats, including containment and recovery strategies.

✨Emphasise Team Collaboration

Since the role involves working with various teams, be ready to discuss your experience in collaborating with others. Share examples of how you've worked effectively in a team environment, especially during high-pressure situations.

B
Similar positions in other companies
UK’s top job board for Gen Z
discover-jobs-cta
Discover now
>